Verified User in Utilities
AU
Verified User in Utilities
Enterprise (> 1000 emp.)
"Easy to use - provides valuable information quickly"
5/5
What do you like best about Carbon Black EDR?

This makes it very easy to search a specific threat domain to see if anyone visited it. Very helpful in analyzing Phishing attempts and if the user actually clicked on them. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Some queries can be complex, requires use of API for some more advanced searching. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Verified User in Computer & Network Security
Small-Business (50 or fewer emp.)
"Fantastic Forensics"
4/5
What do you like best about Carbon Black EDR?

Response hints threats in real time so you get instant intelligence Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Would prefer for the Cb portfolio to all sit as one agent. Review collected by and hosted on G2.com.

Verified User in Government Administration
AG
Verified User in Government Administration
Mid-Market (51-1000 emp.)
"Incident response made easy"
5/5
What do you like best about Carbon Black EDR?

After installling cb Response everyhing is visibel in your environment, and you can search through your events really easy. It doesn't matter what you want to find you can do a search on it very easy. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Configuration is mostly done in conf files, and is not vrey user friendly. Not all supports have a deap linux experiance, whitch can be an problem when the product is based on linux. Review collected by and hosted on G2.com.

Verified User in Investment Management
AI
Verified User in Investment Management
Mid-Market (51-1000 emp.)
"Unrivaled visibility and invaluable IR tool"
4.5/5
What do you like best about Carbon Black EDR?

Our IR team loves the ability to get instant access to what has occurred on our endpoints in the organization. With the ability to instantly get access to the machine through Live response. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

The console can get a bit slow if you haven't put in appropriate filters. Review collected by and hosted on G2.com.

Verified User in Computer Software
EC
Verified User in Computer Software
Mid-Market (51-1000 emp.)
"One of our best security investments"
4.5/5
What do you like best about Carbon Black EDR?

Cb response gives us excellent visibility into our endpoints. We have decided to balance our strategy and focus more on detection and response. We all know if the talented bad guys want to get in, they will. With Cb, I have a virtual video recorder on all my endpoints (servers and workstations) and alerting that is effective. It took us about a month to fine tune. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

The pricing model could improve. Given Cb's recent acquisitions and focus on "beyond AV", having the suite of products, including Protection makes most sense. But I find the pricing to be sometimes complex and expensive for cloud version. Review collected by and hosted on G2.com.

Verified User in Consumer Goods
EC
Verified User in Consumer Goods
Enterprise (> 1000 emp.)
"Best EDR tools around"
4.5/5
What do you like best about Carbon Black EDR?

Integrated Threat Feeds, Integrations with SIEM, Detects threats not found by other methods. Great hunting and response tool. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

It would be nice if there were granular block actions that could be performed by the product. Review collected by and hosted on G2.com.

Verified User in Telecommunications
UT
Verified User in Telecommunications
Enterprise (> 1000 emp.)
"One of the best security products I have used "
5/5
What do you like best about Carbon Black EDR?

Really easy to use and brilliant 'workflow' . The community around this product is also great and it's easy to create rules/watch lists Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Would like to see better search result display options thT can be useful when hunting Review collected by and hosted on G2.com.

Brad M.
BM
Brad M.
Senior Enterprise Systems Engineer
Retail
Mid-Market (51-1000 emp.)
"See Everything on your endpoints"
5/5
What do you like best about Carbon Black EDR?

Carbon Black Enterprise Response provides awesome visibility into your endpoints. Being able to view the process chain of an attack is very useful in learning how the attacks work, preventing them from happening again and educating our users. Very easy to deploy agents and start gathering useful data. Lots of great intelligence feeds. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

I have had some issues with re-occurring alerts even after i have mark them as as Resolved or Resolved False Positive. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Enterprise (> 1000 emp.)
"granular process insight"
3.5/5
What do you like best about Carbon Black EDR?

The granular insight into what process/files are doing what to whom, and when. The watch lists provide a great way to triage suspicious activities and direct daily monitoring and incident response. Integration with CB Enterprise Protection (formerly bit9). Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

We're still tuning, but the enormous amount of standard events are quite a bit to comb through. While it is a monitoring tool, i often have requests to produce reports to illustrate 'what this product is delivering for the company', which i've yet to find a good solution. Review collected by and hosted on G2.com.

Verified User in Electrical/Electronic Manufacturing
UE
Verified User in Electrical/Electronic Manufacturing
Enterprise (> 1000 emp.)
"Carbon Black - Detect and Respond"
5/5
What do you like best about Carbon Black EDR?

Cb has provided us visibility into threat behavior beyond any product out there today. The ability to ban malicious files, create feeds, watch lists, open API, integrations with many other products (and ability to add other products easily), Live Response, isolation and much more, make Cb the differentiator over any other ETDR product on the market today.

Carbon Black provides the ability to also go back in time, which defeats a lot of other products in the space that only can go back a short period of time without disrupting the endpoint. The centralized infrastructure methodology makes sense for Cb as it technically can save money vs other products that will run CPU/mem to the max and begin to overwhelm the workstation/server. Cb is a very lightweight sensor, we see around 0-1% CPU, and 10-28Mb of memory. 28Mb on the high end for instances where it is a busy server like TMG or Exchange.

Cb is deployed to around 60k endpoints with no issues. We've had minor hiccups over time caused by Cb, but nothing widespread and nothing that wasn't fixed on the new patch level etc.

Working with Cb is probably one of the best things about the product. The PM team, engineering, executive team are all great people. Not forgetting the sales team, they are good people too. Everyone at Cb is committed to working and ensuring their product is the best. We have been with Cb since 4.2 and it has really grown a lot since.

the API - is probably one of the most important features to Carbon Black that many products out there fail at. The ability to automate and orchestrate a lot of threat hunting, or even remediation tasks is incredible. Many products fail at this part, or place in API in after the fact. Cb is also 100% committed to ensuring the API is very flexible. They have some of the best developers working it.

Integrations - Cb allows for many integrations, whether ones they've created or ones you create. It's very flexible.

Splunk - we use the cb-event-forwarder to dump most all data to Splunk. This allows us to quickly perform analytics on raw endpoint data. With this, we've taken our detection and response to the next level. Review collected by and hosted on G2.com.

What do you dislike about Carbon Black EDR?

Not a deal breaker in any sense -

1. High availability. Not really an issue since the sensors cache data until the cluster is back online.

2. Cluster upgrade process could be better.

3. Solr has got to go... Review collected by and hosted on G2.com.